plugin

Subscribe2 Vulnerabilities

23 known security issues reported for the Subscribe2 WordPress plugin. Most recent disclosed Aug 3, 2026.

3 high 8 medium

Running Subscribe2 on your site? Check whether your installed version is affected.

Scan your site free

Subscribe2 <= 10.45 - Reflected Cross-Site Scripting

medium

The Subscribe2 plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in versions up to, and including, 10.45 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that execute if they can successfully tric...

CVSS:
6.1
Affected:
up to 10.45
Fixed in:
10.46
Disclosed:
Aug 3, 2026

CVE-2026-14331 on NVD →

Subscribe2 &#8211; Form, Email Subscribers &amp; Newsletters [subscribe2] <= 10.44 (unfixed)

unknown

[en] Missing Authorization vulnerability in weDevs Subscribe2 subscribe2 allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Subscribe2: from n/a through <= 10.44.

Affected:
up to 10.44
Fix:
No patched version reported
Disclosed:
Feb 20, 2026

CVE-2026-24944 on NVD →

Subscribe2 <= 10.44 - Missing Authorization

medium

The Subscribe2 – Form, Email Subscribers & Newsletters plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on a function in all versions up to, and including, 10.44. This makes it possible for unauthenticated attackers to perform an unauthorized action.

CVSS:
5.3
Affected:
up to 10.44
Fixed in:
10.45
Disclosed:
Feb 3, 2026

CVE-2026-24944 on NVD →

Subscribe2 &#8211; Form, Email Subscribers &amp; Newsletters [subscribe2] < 10.44

unknown

[en] The Subscribe2 – Form, Email Subscribers & Newsletters plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ip parameter in all versions up to, and including, 10.43 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitr...

Affected:
up to 10.44
Fixed in:
10.44
Disclosed:
Feb 19, 2025

CVE-2024-11582 on NVD →

Subscribe2 – Form, Email Subscribers & Newsletters <= 10.43 - Unauthenticated Stored Cross-Site Scripting via IP Parameter

high

The Subscribe2 – Form, Email Subscribers & Newsletters plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ip parameter in all versions up to, and including, 10.43 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary w...

CVSS:
7.2
Affected:
up to 10.43
Fixed in:
10.44
Disclosed:
Feb 18, 2025

CVE-2024-11582 on NVD →

Appsero <= 2.0.0 - Missing Authorization via handle_optin_optout

medium

The Appsero analytics tool used in several plugins is vulnerable to unauthorized modification of data due to a missing capability check on the handle_optin_optout function in versions up to, and including, 2.0.0. This makes it possible for unauthenticated attackers to opt-in or opt-out of tracking. This was patched in...

CVSS:
4.3
Affected:
up to 10.42
Fixed in:
10.43
Disclosed:
Apr 11, 2024

CVE-2024-32110 on NVD →

Subscribe2 &#8211; Form, Email Subscribers &amp; Newsletters [subscribe2] < 10.41

unknown

[en] The Subscribe2 plugin for WordPress is vulnerable to unauthorized access to email functionality due to a missing capability check when sending test emails in versions up to, and including, 10.40. This makes it possible for author-level attackers to send emails with arbitrary content and attachments to site users.

Affected:
up to 10.41
Fixed in:
10.41
Disclosed:
Jun 28, 2023

CVE-2023-1844 on NVD →

Subscribe2 &#8211; Form, Email Subscribers &amp; Newsletters [subscribe2] < 10.41

unknown

[en] The Subscribe2 plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 10.40. This is due to missing or incorrect nonce validation when sending test emails. This makes it possible for unauthenticated attackers to send test emails with custom content to users on sites runn...

Affected:
up to 10.41
Fixed in:
10.41
Disclosed:
Jun 28, 2023

CVE-2023-3407 on NVD →

Subscribe2 <= 10.40 - Missing Authorization

medium

The Subscribe2 plugin for WordPress is vulnerable to unauthorized access to email functionality due to a missing capability check when sending test emails in versions up to, and including, 10.40. This makes it possible for author-level attackers to send emails with arbitrary content and attachments to site users.

CVSS:
4.3
Affected:
up to 10.40
Fixed in:
10.41
Disclosed:
Jun 26, 2023

CVE-2023-1844 on NVD →

Subscribe2 <= 10.40 - Cross-Site Request Forgery

medium

The Subscribe2 plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 10.40. This is due to missing or incorrect nonce validation when sending test emails. This makes it possible for unauthenticated attackers to send test emails with custom content to users on sites running a...

CVSS:
4.3
Affected:
up to 10.40
Fixed in:
10.41
Disclosed:
Jun 26, 2023

CVE-2023-3407 on NVD →

Subscribe2 &#8211; Form, Email Subscribers &amp; Newsletters [subscribe2] < 10.38

unknown

[en] The Subscribe2 WordPress plugin before 10.38 does not have CSRF check when deleting users, which could allow attackers to make a logged in admin delete arbitrary users by knowing their email via a CSRF attack.

Affected:
up to 10.38
Fixed in:
10.38
Disclosed:
Jan 16, 2023

CVE-2022-4309 on NVD →

Subscribe2 <= 10.37 - Cross-Site Request Forgery

high

The Subscribe2 plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 10.37. This is due to missing or incorrect nonce validation on the process_bulk_action function. This makes it possible for unauthenticated attackers to delete users, via forged request granted they can tri...

CVSS:
7.1
Affected:
up to 10.37
Fixed in:
10.38
Disclosed:
Dec 22, 2022

CVE-2022-4309 on NVD →

Appsero <= 1.2.1 - Missing Authorization

medium

The Appsero analytics tool used in several plugins is vulnerable to authorization bypass due to a missing capability check on the uninstall_reason_submission function used for feedback submission in versions up to, and including, 1.2.1. This makes it possible for authenticated attackers, with subscriber-level permissio...

CVSS:
4.3
Affected:
up to 10.37
Fixed in:
10.38
Disclosed:
Dec 16, 2022

Appsero <= 1.2.0 - Cross-Site Request Forgery

medium

The Appsero analytics tool used in several plugins is vulnerable to Cross-Site Request Forgery due to a missing nonce check on the uninstall_reason_submission function used for feedback submission in versions up to, and including, 1.2.0. This makes it possible for unauthenticated attackers to invoke this function inten...

CVSS:
4.3
Affected:
up to 10.37
Fixed in:
10.38
Disclosed:
Dec 14, 2022

CVE-2022-47150 on NVD →

Subscribe2 &#8211; Form, Email Subscribers &amp; Newsletters [subscribe2] < 10.38

unknown

The Appsero analytics tool used in several plugins is vulnerable to Cross-Site Request Forgery due to a missing nonce check on the uninstall_reason_submission function used for feedback submission in versions up to, and including, 1.2.0. This makes it possible for unauthenticated attackers to invoke this function inten...

Affected:
up to 10.38
Fixed in:
10.38
Disclosed:
Dec 14, 2022

Subscribe2 &#8211; Form, Email Subscribers &amp; Newsletters [subscribe2] < 10.16

unknown

[en] Cross-site scripting (XSS) vulnerability in class-s2-list-table.php in the Subscribe2 plugin before 10.16 for WordPress allows remote attackers to inject arbitrary web script or HTML via the ip parameter.

Affected:
up to 10.16
Fixed in:
10.16
Disclosed:
Mar 29, 2018

CVE-2014-6604 on NVD →

Subscribe2 &#8211; Form, Email Subscribers &amp; Newsletters [subscribe2] < 8.1

unknown

Because of this vulnerability, the attackers can inject arbitrary JavaScript or HTML code. Update plugin.

Affected:
up to 8.1
Fixed in:
8.1
Disclosed:
May 15, 2015

Subscribe2 – Form, Email Subscribers & Newsletters <= 10.15 - Stored Cross-Site Scripting

medium

The Subscribe2 – Form, Email Subscribers & Newsletters plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the REMOTE_ADDR value in versions up to, and including, 10.15 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers with subscriber, or h...

CVSS:
6.1
Affected:
up to 10.16
Fixed in:
10.16
Disclosed:
Oct 1, 2014

CVE-2014-6604 on NVD →

Subscribe2 – Form, Email Subscribers & Newsletters < 8.1 - Multiple Cross-Site Scripting

high

The Subscribe2 – Form, Email Subscribers & Newsletters plugin for WordPress is vulnerable to Multiple Cross-Site Scripting via several parameters in versions before 8.1 due to insufficient input sanitization and output escaping. This makes it possible for attackers to inject arbitrary web scripts that execute in a vict...

CVSS:
7.1
Affected:
up to 8.1
Fixed in:
8.1
Disclosed:
Aug 1, 2014

Subscribe2 &#8211; Form, Email Subscribers &amp; Newsletters [subscribe2] < 8.1

unknown

The Subscribe2 – Form, Email Subscribers & Newsletters plugin for WordPress is vulnerable to Multiple Cross-Site Scripting via several parameters in versions before 8.1 due to insufficient input sanitization and output escaping. This makes it possible for attackers to inject arbitrary web scripts that execute in a vict...

Affected:
up to 8.1
Fixed in:
8.1
Disclosed:
Aug 1, 2014

Subscribe2 &#8211; Form, Email Subscribers &amp; Newsletters [subscribe2] < 10.38

unknown

** RESERVED ** This candidate has been reserved by an organization or individual that will use it when announcing a new security problem. When the candidate has been publicized, the details for this candidate will be provided.

Affected:
up to 10.38
Fixed in:
10.38

CVE-2022-47150 on NVD →

Subscribe2 &#8211; Form, Email Subscribers &amp; Newsletters [subscribe2] < 8.1

unknown

The Subscribe2 &ndash; Form, Email Subscribers &amp; Newsletters WordPress plugin was affected by a Cross Site Scripting security vulnerability.

Affected:
up to 8.1
Fixed in:
8.1

Subscribe2 &#8211; Form, Email Subscribers &amp; Newsletters [subscribe2] < 10.43

unknown
Affected:
up to 10.43
Fixed in:
10.43

CVE-2024-32110 on NVD →

Protect your WordPress site

Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.

Scan your site free

← Back to the vulnerability database